Skip to main content

roder_core/runtime/
owner_handoff.rs

1//! Planned owner handoff is separate from cancellation-based shutdown.
2use super::Runtime;
3use std::sync::atomic::Ordering;
4
5impl Runtime {
6    /// Permanently seal an owned runtime only after all admitted turns, tool
7    /// futures, and terminal cleanup have finished. Busy runtimes keep working;
8    /// the host must stop new inbound work while polling this operation.
9    ///
10    /// True permits the host to release its durable generation. False means
11    /// work remains. Errors (including persistence failure or lost ownership)
12    /// require recovery; they are not evidence of a successful handoff.
13    pub async fn seal_idle_owner(&self) -> anyhow::Result<bool> {
14        let _admission = self.turn_admission.lock().await;
15        let lease = self
16            .execution_lease
17            .as_ref()
18            .ok_or_else(|| anyhow::anyhow!("owner handoff requires an execution lease"))?;
19        lease.require_live()?;
20        if !self.active_turns.read().await.is_empty() || !self.turn_drains.read().await.is_empty() {
21            return Ok(false);
22        }
23        anyhow::ensure!(
24            self.lifecycle_persistence_failures.load(Ordering::Acquire) == 0,
25            "owner handoff requires reconciliation of failed lifecycle persistence"
26        );
27        if !lease.seal_if_idle()? {
28            return Ok(false);
29        }
30        self.accepting_turns.store(false, Ordering::Release);
31        Ok(true)
32    }
33}